Skip to content

About

Secure IoT device onboarding (provisioning and claiming) for ESP32-S3 using MQTTS on ThingsBoard platform

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Repository files navigation

IoT Homework 4 – Secure ESP32-S3-Touch Communication with ThingsBoard

This repository contains the implementation of Homework 4 for the Fundamentals of Internet of Things course.

The project demonstrates secure IoT communication between an ESP32-S3 device and a local ThingsBoard CE server using MQTT over TLS. It also includes device claiming, auto-provisioning, certificate-based security setup, and an optional LCD/LVGL interface for displaying the device claim code.

Overview

The main goal of this project is to understand how security mechanisms are applied in IoT systems.

In this project, an ESP32-S3 connects to a ThingsBoard server through a secure TLS channel and sends telemetry data such as temperature, humidity, and counter values. The project also explores important IoT lifecycle features such as device claiming and automatic provisioning.

The ThingsBoard server is deployed locally using Docker Compose and configured with TLS certificates generated through a custom PKI setup.

Features

  • ESP32-S3 connection to ThingsBoard
  • MQTT over TLS using port 8883
  • One-way TLS authentication
  • Local ThingsBoard CE deployment using Docker Compose
  • PostgreSQL database for ThingsBoard
  • Custom CA and server certificate setup
  • Secure telemetry transmission
  • Device claiming workflow
  • Auto-provisioning workflow
  • ThingsBoard claiming dashboard JSON
  • Optional LCD/LVGL interface for displaying claim code
  • PKI folder containing CA, server, and client certificate materials

Technologies and Tools

  • ESP32-S3
  • Arduino Framework
  • C++
  • ThingsBoard CE
  • MQTT
  • TLS / SSL
  • Docker Compose
  • PostgreSQL
  • WiFiClientSecure
  • ThingsBoard Arduino SDK
  • Arduino MQTT Client
  • PubSubClient
  • ArduinoJson
  • LVGL
  • ESP Display Panel

Repository Structure

.
├── one-way-TLS.ino
├── Claiming.ino
├── Auto-Provisioning.ino
├── docker-compose.yml
├── claiming.json
├── certs/
│   ├── root-ca.pem
│   ├── server.pem
│   └── server.key
├── pki/
│   ├── ca/
│   ├── server/
│   └── client/
├── lcd/
│   └── sketch_jul6a/
│       ├── sketch_jul6a.ino
│       ├── lvgl_v8_port.cpp
│       ├── lvgl_v8_port.h
│       └── esp_panel_board_custom_conf.h
└── lv_conf.h

Main Parts

1. One-Way TLS

File:

one-way-TLS.ino

This sketch demonstrates secure telemetry transmission from ESP32-S3 to ThingsBoard using MQTT over TLS.

The ESP32-S3 verifies the ThingsBoard server certificate using the root CA certificate and then sends telemetry data securely.

Telemetry values include:

  • Temperature
  • Humidity
  • Counter value

The general flow is:

ESP32-S3
  ↓
Wi-Fi
  ↓
WiFiClientSecure
  ↓
MQTT over TLS
  ↓
ThingsBoard CE

2. Device Claiming

File:

Claiming.ino

This sketch implements the ThingsBoard device claiming workflow.

The ESP32-S3 generates a random claim code and sends a claim request to ThingsBoard. The user can then enter this code in the ThingsBoard UI to claim ownership of the device.

This feature is important in IoT systems because it allows a physical device to be securely assigned to a specific user or customer after deployment.

3. Auto-Provisioning

File:

Auto-Provisioning.ino

This sketch implements automatic device provisioning.

The ESP32-S3 connects to ThingsBoard using provisioning credentials and requests a device token. After successful provisioning, the device uses the received token to connect and send telemetry data.

This simulates a real-world IoT onboarding process where devices can be registered automatically without manually creating each device in the platform.

4. ThingsBoard with TLS

File:

docker-compose.yml

The project includes a Docker Compose configuration for running ThingsBoard CE with PostgreSQL.

The ThingsBoard MQTT TLS listener is enabled on port 8883 using PEM certificate files.

Main exposed ports include:

8080  → ThingsBoard Web UI
1883  → MQTT
8883  → MQTT over TLS
5432  → PostgreSQL

5. PKI and Certificates

Folders:

certs/
pki/

The project contains certificate materials used for TLS configuration.

The PKI structure includes:

  • Root CA certificate
  • Server key and certificate
  • Client certificate files
  • CSR and configuration files

These files are used to configure ThingsBoard and allow the ESP32-S3 to verify the server identity.

Note: Real private keys and tokens should not be published in a public repository. For public use, replace them with sample certificates or document how to generate new ones.

6. LCD / LVGL Claiming Demo

Folder:

lcd/sketch_jul6a/

This optional part adds a display interface using LVGL.

The ESP32-S3 shows the ThingsBoard claiming status and claim code directly on the LCD, making the device claiming process more user-friendly.

Displayed information includes:

  • Connection status
  • ThingsBoard connection result
  • Claim code
  • Claiming instructions

Running ThingsBoard Locally

Start the ThingsBoard server:

docker compose up -d

Then open the ThingsBoard UI in the browser:

http://localhost:8080

The secure MQTT endpoint is available on:

mqtts://<server-ip>:8883

ESP32-S3 Setup

Before uploading the sketches, update the following values according to your local setup:

constexpr char WIFI_SSID[] = "YOUR_WIFI_SSID";
constexpr char WIFI_PASSWORD[] = "YOUR_WIFI_PASSWORD";

constexpr char THINGSBOARD_SERVER[] = "YOUR_THINGSBOARD_SERVER_IP";
constexpr uint16_t THINGSBOARD_PORT = 8883U;

For token-based examples:

constexpr char TOKEN[] = "YOUR_DEVICE_TOKEN";

For claiming examples:

constexpr char DEVICE_TOKEN[] = "YOUR_DEVICE_TOKEN";

For provisioning examples:

constexpr char PROVISION_KEY[] = "YOUR_PROVISION_KEY";
constexpr char PROVISION_SECRET[] = "YOUR_PROVISION_SECRET";

Required Arduino Libraries

Install the following libraries in Arduino IDE:

ThingsBoard
Arduino_MQTT_Client
PubSubClient
ArduinoJson

For the LCD/LVGL version, also install and configure:

LVGL
ESP Display Panel

Security Notes

This project demonstrates several important IoT security concepts:

  • TLS prevents telemetry data from being sent in plaintext.
  • The ESP32-S3 verifies the server certificate using the root CA.
  • MQTT communication is protected through WiFiClientSecure.
  • Device tokens are used for device authentication.
  • Device claiming helps assign ownership of a deployed device.
  • Auto-provisioning simplifies large-scale device onboarding.

For public repositories, do not commit real credentials, Wi-Fi passwords, tokens, provisioning secrets, or private keys.

Authors

This project was implemented by:

  • Millad Ansari(MiladAnsari)
  • Seyed Sadra Mousavi (SMousavi7)

Educational Purpose

This repository was developed for educational purposes as part of an Internet of Things course. It is intended to demonstrate secure IoT communication, TLS configuration, device claiming, and provisioning concepts using ESP32-S3 and ThingsBoard.

About

Secure IoT device onboarding (provisioning and claiming) for ESP32-S3 using MQTTS on ThingsBoard platform

Topics

Resources

Stars

5 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages